HR Technology AI & Compliance

Who Owns It When Your AI Hiring Tool Gets Sued? 4 Critical Points to Accountability

HR Technology · AI Hiring 7 min read

A handful of recent court cases have surfaced a question almost nobody inside AI-adopting companies had asked before the filings landed: who was actually responsible for what the software was doing? In one, Workday disclosed in court filings last May that its software had rejected 1.1 billion job applications during the period at issue in a class action. Mobley v. Workday was certified as a nationwide collective action covering every applicant over 40.

A second lawsuit filed in January 2026 against Eightfold AI made the pattern harder to ignore. Named plaintiff Erin Kistler alleged the tool scraped data on more than a billion workers and scored them on a zero-to-five scale, with low-ranked applicants discarded before any human saw their materials. Eightfold's client list included Microsoft, PayPal, Morgan Stanley, Starbucks and Chevron. "I think I deserve to know what's being collected about me and shared with employers," Kistler told reporters.

"If the AI in the HR system is not properly designed or used, it can scale discrimination to the likes that we have never seen before."

— Keith Sonderling, Former EEOC Commissioner

Is the AI Hiring Tool Responsible?

As these patterns unfold across more companies, the answer to who owns the software's decisions is uncomfortable: at most organizations, it's nobody. Vendors didn't own it. HR didn't own it. Legal never saw it. And these are no longer fringe cases — SHRM's 2026 report put AI adoption for HR tasks at 43%, nearly double the 26% recorded a year earlier, the fastest rollout of any HR technology in the past decade.

Yet only 49% of organizations using or piloting these tools have any policies around them, and just 25% of those consider their policies clear enough to hold up. Tools arrived before rules did, and the gap keeps widening.

Vendor Contracts Won't Save You

Every employment attorney examining this keeps returning to the vendor agreements. An analysis by Jones Walker and Gouchev Law found that 88% of AI vendor contracts cap their own liability, often limiting damages to a single month's subscription fee. Only a third provide any indemnification for third-party claims — meaning when a class action hits, the contract leaves the employer holding the full loss. Set against Mobley, where the alleged harm spans 1.1 billion application decisions, a monthly fee covers nothing.

The risk isn't hypothetical. Stanford researchers tested AI resume-screening tools in October 2025 and found older male candidates rated higher than female and younger candidates — even though every resume drew from identical data. As Sonderling also noted, "When you talk about the black box of the algorithm, what about the black box of the human brain?" A well-audited system creates a better paper trail than a hiring manager's gut. AI itself isn't the problem; the problem is that you cannot defend a system you are not testing.

"Ownership of the human impact of AI cannot sit anywhere but HR."

— Udbhav Ganjoo, Head of HR for Global Operations, Viatris

Nobody Is Watching

Regulation is arriving, but unevenly. Colorado's AI Act took effect June 30, 2026, requiring written impact assessments before deploying high-risk AI, a documented risk-management program, and candidate disclosure. Illinois passed its own law effective January 2026, and California demands four-year data retention plus trained human oversight with real override capability. Three states, three different sets of rules — and 57% of HR professionals in states with these laws don't know they exist.

Even the flagship example underwhelms. New York City's Local Law 144 required bias audits for automated hiring tools, but the NYC Comptroller's audit of enforcement from July 2023 through June 2025 found 75% of 311 calls about AI hiring were misrouted and never reached the right agency. Enforcement staff surveyed 32 companies and flagged one case of non-compliance; the Comptroller's own auditors identified at least 17 potential violations at those same firms. On paper the law existed. In practice it barely functioned.

Who Should Own This

If accountability belongs with HR, most HR leaders aren't in the room. Pinnacle's 2026 survey of enterprise CHROs found only 21% are closely involved in AI decisions; 92% said they participate at "some level" — a polite way of saying most are briefed, not deciding. Betsy Summers at Forrester would push back on the pace itself: "I would slow down. I don't think that speed to value is the right selling point here."

The disconnect runs deep. Mercer found fewer than one in four CEOs have said anything publicly about how AI will affect jobs, and fewer than one in five employees have heard from their managers about it. Gartner reports only 26% of candidates trust AI to evaluate them fairly, while 52% believe their applications are already being screened by it. Maggie Ruvoldt, CHRO at Learn Behavioural, offered the practical line: "All the yeses can automatically move forward, but all the no's have to be reviewed by somebody." Or, as Valoir's Rebecca Wettemann put it, vendors must explain their algorithms to your satisfaction, not theirs.

A 4-Point Accountability Checklist

Before the next AI hiring lawsuit becomes your problem, answer these four questions in writing. If you can't answer one without asking somebody else, you've found a gap.

1. Who signed the vendor contract, and have they read the liability cap? Pull the agreement, find the indemnification clause and the damages cap, and confirm the signer can explain both in plain language. The Jones Walker data suggests you probably aren't covered for the scale of damages seen in cases like Mobley.

2. Who reviews the rejections before they go out? This is the Ruvoldt test. Every candidate the system rejects should have a human checking the decision before it's final. Without a human in the loop, you're rubber-stamping an algorithmic decision — and the accountability is yours.

3. When was the tool last audited, and by whom? Bias testing belongs on the calendar at least twice a year, run by an independent third party rather than the vendor. If your only audit happened at implementation, assume you have a current problem — models drift and training data ages.

4. Do your candidates know AI is involved? Some states already require disclosure, and more follow each quarter. If your candidate-facing communication doesn't mention AI, fix that before a candidate — or a regulator — asks. Keep the full list somewhere procurement, HR and legal can all see it. That's what accountability looks like in practice, and it's far cheaper than the alternative.

Key Takeaways
1

The accountability gap is real. At most companies no one owns AI hiring decisions — not the vendor, not HR, not legal — even as lawsuits like Mobley v. Workday reach billions of decisions.

2

Contracts shift the risk to you. 88% of AI vendor contracts cap liability, often at one month's fee, and only a third indemnify third-party claims — leaving employers exposed in a class action.

3

Regulation is fragmenting fast. Colorado, Illinois and California each impose different rules, yet 57% of HR pros in those states don't know the laws exist — and existing enforcement is weak.

4

Human review and audits are non-negotiable. Every rejection needs a human check, and tools should be independently bias-audited twice a year because models drift over time.

5

Ownership belongs with HR. Accountability for AI's human impact sits with HR, yet only 21% of CHROs are closely involved in AI decisions — a gap leaders need to close now.